What "audited no-logs" really means

· 6 min read

A no-logs policy is a promise. An audit is somebody outside the company checking whether the promise matches the servers. The difference matters, but audits are narrower than the marketing suggests.

What an audit checks

An auditor from a firm such as Deloitte, PwC, Securitum or Cure53 is given access to server configurations, internal policies and sometimes source code. They confirm whether systems are capable of storing activity that could identify a user.

What an audit does not prove

An audit is a snapshot of a moment in time, usually of a sample of servers. It cannot prove that nothing changed the week after. That is why frequency matters: a provider audited every year tells you more than one audited once in 2019.

How to read a report

Look for four things before you trust a claim.

  • The scope — which systems and how many servers were examined
  • The date — anything older than two years is weak evidence
  • The auditor — a named, recognised firm, not an unnamed consultant
  • Availability — the full report, not just a press release summary

Court records beat audits

The strongest evidence is a provider that was legally compelled to hand over data and had nothing to give. Several providers on our list have that record, which is worth more than any single report.

Frequently asked

How many VPNs on your list are audited?

Seven of the eight we compare have completed at least one independent audit. IPVanish has not.

Does jurisdiction still matter if a VPN keeps no logs?

Less than it used to. If there is nothing stored, there is nothing to hand over — but a privacy-friendly jurisdiction reduces the pressure to start storing.

Find your match in 30 seconds

Filter 8 tested VPNs by use case, budget and must-have features.

Open the VPN finder →

Keep reading